Home

Description

EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED Reserved 2025-07-28 | Published 2025-08-06 | Updated 2025-08-06 | Assigner huawei




HIGH: 7.3CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Problem types

CWE-840 Business Logic Errors

Product status

Default status
unaffected

4.3.1
affected

4.3.0
affected

4.2.0
affected

4.0.0
affected

3.1.0
affected

3.0.0
affected

2.1.0
affected

2.0.0
affected

Default status
unaffected

15.0.0
affected

14.0.0
affected

13.0.0
affected

12.0.0
affected

References

consumer.huawei.com/en/support/bulletin/2025/8/

cve.org (CVE-2025-54611)

nvd.nist.gov (CVE-2025-54611)

Download JSON